-
Notifications
You must be signed in to change notification settings - Fork 0
133 lines (121 loc) · 5.08 KB
/
Copy pathrelease-please.yml
File metadata and controls
133 lines (121 loc) · 5.08 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
name: Release Please
# Maintains a standing "chore(release): X.Y.Z" PR against main, auto-updated
# as commits land. Merging it bumps package.json + CHANGELOG.md, pushes the
# vX.Y.Z tag and creates the GitHub release (all by release-please itself),
# then the publish job below pushes the tagged commit to npm. Same setup as
# rvnflt's release-please.yml.
#
# token is a GitHub App installation token, not the default GITHUB_TOKEN:
# events authored by GITHUB_TOKEN don't trigger other workflows, so the
# release PR would open without CI ever running on it. RELEASE_BOT_CLIENT_ID /
# RELEASE_BOT_APP_PRIVATE_KEY are org-level secrets shared with the sibling
# repos.
#
# npm publishing currently uses an NPM_TOKEN secret, not trusted publishing
# (see the publish steps); the trusted publisher entries on npmjs.com should
# still name this repo, this workflow file (release-please.yml) and the `npm`
# environment so it can switch back once npm supports immutable OIDC subjects.
on:
push:
branches: [main]
# Manual republish of an existing release's tag (e.g. after fixing npm
# trusted-publisher config); skips release-please and only runs `publish`.
workflow_dispatch:
inputs:
tag:
description: "Existing release tag to publish to npm (e.g. v0.7.0)"
required: true
type: string
permissions: {}
jobs:
release-please:
name: Release Please
if: github.event_name == 'push'
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: write
pull-requests: write
outputs:
release_created: ${{ steps.release.outputs.release_created }}
tag_name: ${{ steps.release.outputs.tag_name }}
steps:
- name: Generate App token
id: app-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
client-id: ${{ secrets.RELEASE_BOT_CLIENT_ID }}
private-key: ${{ secrets.RELEASE_BOT_APP_PRIVATE_KEY }}
permission-contents: write
permission-pull-requests: write
- uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5.0.0
id: release
with:
token: ${{ steps.app-token.outputs.token }}
target-branch: main
config-file: release-please-config.json
manifest-file: .release-please-manifest.json
publish:
name: Publish to npm
needs: release-please
if: >-
!cancelled() &&
(needs.release-please.outputs.release_created == 'true' || github.event_name == 'workflow_dispatch')
runs-on: ubuntu-latest
timeout-minutes: 10
environment: npm
permissions:
contents: read
id-token: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ inputs.tag || needs.release-please.outputs.tag_name }}
persist-credentials: false
# Trusted publishing needs npm >= 11.5.1, which ships with Node 24.
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24
registry-url: https://registry.npmjs.org
- name: Check package.json version matches tag
env:
TAG: ${{ inputs.tag || needs.release-please.outputs.tag_name }}
run: |
set -euo pipefail
PKG_VERSION=$(jq -r .version package.json)
if [ "v${PKG_VERSION}" != "$TAG" ]; then
echo "::error::package.json version ${PKG_VERSION} does not match tag ${TAG}." >&2
exit 1
fi
JSR_VERSION=$(jq -r .version jsr.json)
if [ "${JSR_VERSION}" != "${PKG_VERSION}" ]; then
echo "::error::jsr.json version ${JSR_VERSION} does not match package.json ${PKG_VERSION}." >&2
exit 1
fi
# JSR is linked to this repo so trusted publishing Just Works^TM
- name: Publish @taraxvoid/voidflow to JSR
run: |
set -euo pipefail
npm install --no-save --no-package-lock --ignore-scripts @playwright/test
npx --yes jsr publish
# Publishes with the NPM_TOKEN secret (granular token scoped to both
# packages, stored on the `npm` environment) as a stopgap: npm's trusted
# publishing rejects GitHub's immutable OIDC subject claims, which this
# repo can't opt out of (npm/cli#9969). Provenance still works via
# id-token: write. Once npm fixes that, delete the NPM_TOKEN secret and
# these NODE_AUTH_TOKEN lines to fall back to pure OIDC; the trusted
# publisher entries (this repo, release-please.yml, `npm` environment)
# are already configured on both packages.
- name: Publish @taraxvoid/voidflow to NPM (scoped canonical package)
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
run: npm publish
# Unscoped mirror of the same tarball, so `npm add -d voidflow` and
# `npx voidflow` work.
- name: Publish voidflow (unscoped mirror)
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
run: |
set -euo pipefail
npm pkg set name=voidflow
npm publish